How to automate exposure verification at the speed of AI attacks

hacker newsApril 29, 2026Artificial intelligence/exposure verification In February 2026, researchers discovered a change that changed the situation forever. Attackers are using custom AI setups to automate attacks directly into the kill chain. We’re no longer just talking about AI creating better phishing emails. We’re talking about an autonomous agent that maps Active Directory and retrieves […]

What to look for in an exposure management platform (and what most of it is wrong with)

Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities resolved. The dashboard is full of green. Then someone in the leadership council asks, “So are we actually safer now?” Crickets. The room falls silent because honest answers require context. Patch counts and CVSS scores are not designed […]

CISA adds actively exploited ConnectWise and Windows flaws to KEV

Ravi LakshmananApril 29, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws affecting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerabilities are listed below. CVE-2024-1708 (CVSS Score: 8.4) – A path traversal vulnerability in ConnectWise ScreenConnect […]

LiteLLM CVE-2026-42208 SQL injection can be exploited within 36 hours of publication.

Ravi LakshmananApril 29, 2026Vulnerability / Cloud Security In yet another example of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package was actively exploited in the wild within 36 hours of the bug becoming public knowledge. This vulnerability, tracked as CVE-2026-42208 (CVSS score: 9.3), is […]

Researchers have discovered a critical GitHub CVE-2026-3854 RCE flaw that can be exploited via a single Git push

Ravi LakshmananApril 28, 2026Vulnerabilities/Software Security Cybersecurity researchers have detailed a critical security vulnerability affecting GitHub.com and GitHub Enterprise Server. This vulnerability could allow an authenticated user to execute remote code with a single “git push” command. This flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a case of command injection that could allow an attacker […]

Brazil’s LofyGang resurfaces after 3 years with Minecraft LofyStealer campaign

A cybercrime group of Brazilian origin has resurfaced after more than three years and organized a campaign targeting Minecraft players using a new stealer called LofyStealer (also known as GrabBot). “This malware disguises itself as a Minecraft hack called ‘Slinky,’” Brazil-based cybersecurity firm ZenoX said in a technical report. “It exploits young users’ trust in […]

Why secure data movement is the Zero Trust bottleneck that no one talks about

All security programs are based on the same premise: once the system is connected, the problem is resolved. Open a ticket, launch a gateway, and push data through. end. That assumption is wrong. This is also the main reason why Zero Trust programs stall. A new study my team just published shows the numbers. The […]

Unpatched critical flaw exposes Hugface LeRobot to uncertified RCE

Ravi LakshmananApril 28, 2026Vulnerability/Network Security Cybersecurity researchers have detailed a critical security flaw affecting LeRobot, Hugging Face’s open-source robotics platform, which has approximately 24,000 GitHub stars. This could be exploited to lead to remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which is described as a case of untrusted data deserialization […]